Storm-2945 uses hotel Wi-Fi fake updates to deploy CornFlake RAT
Source headline: Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
Intelligence Summary
A hijacked hotel Wi-Fi network was used to deliver a fake browser update. The update served the CornFlake remote access trojan to victims who visited captive portals. Microsoft reports that the malware can capture webcam images, microphone audio, and keystrokes. Researchers link the operation, dubbed CaptiveCrunch, to Storm-2945. This matters because shared Wi-Fi plus user-driven update prompts can lead to full device surveillance and credential theft. Users should avoid installing updates prompted through captive portals and keep browsers and OS components up to date.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.